OpenSSL - Alternative chains certificate forgery
- https://openssl.org/news/secadv_20150709.txt
9 Jul 2015
Severity: High
This issue will impact any application that verifies certificates including
SSL/TLS/DTLS clients and SSL/TLS/DTLS servers using client authentication.
This issue affects OpenSSL versions 1.0.2c, 1.0.2b, 1.0.1n and 1.0.1o.
OpenSSL 1.0.2b/1.0.2c users should upgrade to 1.0.2d
OpenSSL 1.0.1n/1.0.1o users should upgrade to 1.0.1p …
- https://openssl.org/source/
Jul 9 12:42:53 2015 openssl-1.0.1p.tar.gz
Jul 9 12:42:53 2015 openssl-1.0.2d.tar.gz
OpenSSL patches Multiple Vulnerabilities
- https://www.us-cert.gov/ncas/current-activity/2015/12/03/OpenSSL-Patches-Multiple-Vulnerabilities
Dec 03, 2015 - "OpenSSL has released updates patching -four- vulnerabilities. Exploitation of -one- of these vulnerabilities could allow an attacker to cause a cause a Denial of Service condition. Updates available include:
OpenSSL 1.0.2e for 1.0.2 users
OpenSSL 1.0.1q for 1.0.1 users
OpenSSL 1.0.0t for 1.0.0 users
OpenSSL 0.9.8zh for 0.9.8 users…"
- http://www.securitytracker.com/id/1034294
CVE Reference: CVE-2015-1794, CVE-2015-3193, CVE-2015-3194, CVE-2015-3195, CVE-2015-3196
Dec 5 2015
Impact: A remote user can cause the target service to crash.
A remote user can obtain potentially sensitive information on the target system.
Solution: The vendor has issued a fix (0.9.8zh, 1.0.0t, 1.0.1q, 1.0.2e).
OpenSSH 7.1p2 released
- https://isc.sans.edu/diary.html?storyid=20613
2016-01-14 - "… this is -not- as serious as previous OpenSSH vulnerabilities like Heartbleed.
OpenSSH 7.1p2 has been released with a security fix for a vulnerability recently assigned to CVE-2016-0777* [1]. CVE 2016-0777 is a client information leak that could leak private keys to a malicious server. A workaround is available for previous versions of OpenSSH [2]… This bug has similarities to the 2014 Heartbleed vulnerability that affected the OpenSSL crypto library. Heartbleed was much more serious, because the bug made it possible for anyone with moderate hacking skills to exploit any website using OpenSSL. By contrast, the OpenSSH bug can only be exploited after a vulnerable end user connects to a maliciously-configured server [5]."
* http://www.openssh.com/txt/release-7.1p2
OpenSSL 1.0.2f, 1.0.1r released
- https://www.openssl.org/news/secadv/20160128.txt
28 Jan 2016
"… OpenSSL 1.0.2 users should upgrade to 1.0.2f…
… OpenSSL 1.0.1 users should upgrade to 1.0.1r …"
- http://www.securitytracker.com/id/1034849
CVE Reference: CVE-2015-3197, CVE-2016-0701
Jan 28 2016
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 1.0.1, 1.0.2 …
Impact: A remote user can recover keys in certain cases.
A remote user can negotiate disabled ciphers.
Solution: The vendor has issued a fix (1.0.1r, 1.0.2f) …
OpenSSL 1.0.1s, 1.0.2g released
- https://www.openssl.org/news/secadv/20160301.txt
1 March 2016
"Severity: High
OpenSSL 1.0.2 users should upgrade to 1.0.2g
OpenSSL 1.0.1 users should upgrade to 1.0.1s …"
- http://www.securitytracker.com/id/1035133
CVE Reference: CVE-2016-0702, CVE-2016-0703, CVE-2016-0704, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-0800
Mar 1 2016
Impact: A remote user can decrypt TLS sessions in certain cases.
A remote user can cause denial of service conditions.
Solution: The vendor has issued a fix (1.0.1s, 1.0.2g)…
- https://isc.sans.edu/diary.html?storyid=20789
2016-03-02 - "… Decrypting RSA with Obsolete and Weakened eNcryption, or 'DROWN', have surfaced that takes advantage of a weakness in SSLv2. The most significant impact of this vulnerability to date relates to OpenSSL, which released an update.. that addresses this vulnerability, and several others. The US-CERT published a notification*.. stating "Network traffic encrypted using an RSA-based SSL certificate may be decrypted if enough SSLv2 handshake data can be collected." Microsoft IIS version 7.0 and greater is not impacted, as SSLv2 is -disabled- by default; unless it has been enabled as part of the deployment, which should be identified during vulnerability testing. While secure default configurations, patches, and updates will often address the technical shortcomings in applications and libraries, it will -not- address architectural issues where integrations exist which rely on older encryption methods…"
* https://www.kb.cert.org/vuls/id/583776
Last revised: 02 Mar 2016
- http://www.theregister.co.uk/2016/03/02/drown_proves_people_didnt_test_their_servers_after_poodle/
2 Mar 2016 - "… The DROWN flaw in HTTPS would not be anything to worry about, except that developers working on server-side software made the fatal assumption that since there were no clients left to request a deprecated SSL connection, they didn't need to update their code to -kill- older SSL completely… In other words: if you believed your configuration was secure -without- going back to test it, you may have ticked all the boxes in your “best practice” list and -remain- vulnerable…"
OpenSSL 1.0.2h, 1.0.1t released
- https://www.openssl.org/news/secadv/20160503.txt
3 May 2016
"Severity: High
OpenSSL 1.0.2 users should upgrade to 1.0.2h
OpenSSL 1.0.1 users should upgrade to 1.0.1t …"
- http://www.securitytracker.com/id/1035721
CVE Reference: CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176
May 3 2016
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to versions 1.0.1t, 1.0.2h …
Impact: A remote user can decrypt traffic in certain cases.
A remote or local user may be able to execute arbitrary code on the target application that uses OpenSSL.
A remote or local user can cause denial of service conditions on the target system.
A remote user can obtain potentially sensitive information on the target system.
Solution: The vendor has issued a fix (1.0.1t, 1.0.2h)…
OpenSSL 1.0.1u, 1.0.2i, 1.1.0a released
- https://www.openssl.org/news/secadv/20160922.txt
22 Sep 2016 - "Severity: High …
OpenSSL 1.1.0 users should upgrade to 1.1.0a
OpenSSL 1.0.2 users should upgrade to 1.0.2i
OpenSSL 1.0.1 users should upgrade to 1.0.1u …"
> https://isc.sans.edu/diary.html?storyid=21509
2016-09-22 - "OpenSSL released an update today for all currently supported versions (1.0.1, 1.0.2, 1.1.0).
The update fixes -14- different vulnerabilities… With this update, the latest versions of OpenSSL for the various branches are 1.0.1u, 1.0.2i and 1.1.0a. All three branches are currently supported…" (See chart @ the isc URL above.)
___
- http://www.securitytracker.com/id/1036878
CVE Reference: CVE-2016-6304
Sep 22 2016
Fix Available: Yes Vendor Confirmed: Yes
Version(s): 1.0.1, 1.0.2, 1.1.0…
Impact: A remote authenticated user can consume excessive memory resources on the target system.
Solution: The vendor has issued a fix (1.0.1u, 1.0.2i, 1.1.0a)…
- http://www.securitytracker.com/id/1036879
CVE Reference: CVE-2016-6305
Sep 22 2016
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
Version(s): 1.1.0…
Impact: A remote authenticated user can cause the target service to hang.
Solution: The vendor has issued a fix (1.1.0a)…
- http://www.securitytracker.com/id/1036885
CVE Reference: CVE-2016-6302, CVE-2016-6303, CVE-2016-6306, CVE-2016-6307, CVE-2016-6308, CVE-2016-6309, CVE-2016-7052
Updated: Sep 26 2016
Fix Available: Yes Vendor Confirmed: Yes
Impact: A remote user can cause the target service or application to crash.
Solution: The vendor has issued a fix (1.0.1u, 1.0.2i, 1.1.0a).
[Editor's note: On September 26, 2016, the vendor reported that two of the fixed versions contain vulnerabilities. Version 1.1.0a is affected by a use-after-free memory error (CVE-2016-6309), reported by Robert Swiecki (Google Security Team). Version 1.0.2i is affected by a CRL processing null pointer exception (CVE-2016-7052), reported by Bruce Stephens and Thomas Jakobi. The revised fixes are versions 1.1.0b and 1.0.2j.]
___